Open any cleared cybersecurity job posting this week and there is a good chance it asks for a certification "per DoD 8570" or names an "IAT Level II baseline." I have seen it in postings written this year, in contract statements of work, and in the certification table on my own website until I corrected it while writing this.
DoD 8570 has not been the governing policy since 15 February 2023. It was superseded on the release of DoD Manual 8140.03, the Cyberspace Workforce Qualification and Management Program (DoD Cyber Exchange transition paper, retrieved 3 September 2026). That is more than three years of a retired framework being cited as a current requirement.
This is not pedantry about a document number. The replacement changed the substance of how people qualify, and the change works in favor of experienced practitioners in a way that almost nobody is taking advantage of.
The part everyone gets wrong
Under the old model, the mental shortcut was simple and mostly accurate: find your category and level, hold one of the listed certifications, and you are compliant. A cert was the ticket. That shortcut is why the entire defense hiring market still thinks in terms of "do you have Security+."
DoDM 8140.03 does not work that way. Qualification is now tied to a specific work role in the DoD Cyber Workforce Framework, and the foundational portion offers three options, not one. Per the manual, personnel must "complete any one of the three foundational qualification options":
Education. A secondary diploma at minimum, with higher education evaluated against the work role.
Training. Coursework that covers 70 percent of the core task and knowledge, skills and abilities content for that role.
Personnel certification. A certification accredited to ISO/IEC 17024.
Any one of the three satisfies the foundational requirement. A certification is a path, not the path. I have watched capable people conclude they were locked out of a role because they did not hold a specific four-letter credential, when the education or training path was open to them the whole time.
Foundational is only half of it
The second half is the piece that has no equivalent in the old framework, and it is the one hiring managers should care about most. Alongside the foundational area, 8140.03 requires residential qualification: a formal period of supervised engagement covering the task and knowledge, skills and abilities content for the role before the individual works unsupervised.
Read that again with an operational eye. The policy now says out loud that holding a certificate does not mean you can do the job, and it builds a supervised on-the-job period into the qualification itself. Anyone who has watched a freshly certified technician meet a live accreditation boundary for the first time understands exactly why that clause exists.
There is also continuous professional development on top of both, which is the part that most resembles the old continuing-education cycle.
The two clocks
The manual attaches deadlines to assignment, not to hiring or to fiscal year:
- Foundational qualification within 9 months of assignment to a cyberspace work role.
- Residential qualification within 12 months of assignment to that role.
Missing either one requires removal from the role unless a waiver is granted. That is a materially different posture from the old one, where a lapse tended to surface as an administrative finding during an inspection and then sat in a tracker.
I have some personal history with exactly that failure mode. My own Security+ lapsed in 2018 and nothing in the system caught it for years, which I wrote about honestly rather than quietly fixing. Under a clock tied to assignment with removal as the consequence, that gap is visible far sooner. This is an improvement, and I say that as someone it would have caught.
If you are writing the job posting
Three things are worth correcting, and none of them cost anything:
- Cite the current policy. A posting that says "DoD 8570 IAT Level II" tells a knowledgeable candidate that the requirement was copied from an old template. That is a small credibility leak in a market where the candidates you most want are the ones who notice.
- Name the work role, not just the certification. The framework is role-based now. Naming the role tells a candidate what the job actually is and lets them map their own qualification path to it.
- Stop screening on a single certification. If the policy accepts three foundational paths and your filter accepts one, you are rejecting qualified people for a requirement the government did not impose. In a market this tight for cleared talent, that is a self-inflicted wound.
If you are the candidate
The practical read is less dramatic than it sounds. Certifications remain the cleanest, most portable evidence, because they travel between employers and clear automated filters that were built during the 8570 era and never updated. A recruiter's applicant tracking system does not read DoD manuals.
So the honest advice is to hold the certification anyway, while knowing three things the average applicant does not:
- You are not disqualified by the absence of one specific credential, and you can say so accurately, with the policy behind you.
- Documented training and relevant education count against the foundational requirement, so the study you have already done may not be wasted.
- Your supervised operational record is now part of the qualification model rather than a soft factor. If you have run the program, passed the inspections, and held the boundary, that is on-policy evidence, not just a talking point.
That last point is the one I would emphasize if you are transitioning. The framework moved toward what you actually did, and away from what you can produce a PDF for.
What I changed on this site
Writing this cost me a correction. My own certification tracker cited the "DoD 8570 Baseline" next to Security+, which is the exact error I am describing. I fixed it the same day. A current Information System Security Manager citing a framework retired three years ago is not a good look, and I would rather find it myself than have a hiring manager find it for me.
The one thing I would not do is treat the qualification matrix as settled. The certification-to-role mappings and proficiency tiers are maintained separately from the manual and are revised on their own schedule, and the authoritative view for a specific role sits behind DoD access. If you need the answer for a particular billet, confirm it through your command or DoD COOL rather than through any article, including this one.
If you are transitioning out of a cleared role and trying to work out which credentials actually matter for where you are going, that is a conversation worth having and I am happy to have it. Reach me at travis@buteranet.com.
Travis D. Butera